Configuring an IPv4 PBR Policy with a Tunnel as the Next Hop

Traffic can be configured to route over an IPsec tunnel or GRE tunnel using PBR. The following steps configure an IPsec or GRE tunnel interface as the next hop of a PBR route map.

You must configure the IPsec tunnel or GRE tunnel before configuring the traffic to route over a tunnel. For more information about IPsec tunnel configuration, refer to the Routing Traffic over an IPsec Tunnel Using PBR task. For more information about GRE tunnel configuration, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Define the required IPv4 ACLs to be added to the route map.
    device(config)# ip access-list standard 99 
    device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
  3. Enter the route-map command to define the route and specify the match criteria and the resulting action if all the match clauses are met.
    device(config)# route-map test-route permit 99
  4. Add IPv4 ACLs to match the IP address that is permitted by the ACL.
    device(config-routemap test-route)# match ip address 99
  5. Set the configured tunnel as the next hop for a route map.
    device(config-routemap test-route)# set next-hop-ip-tunnel 1
  6. Enter the end command to return to global configuration mode.
    device(config-routemap test-route)# end
  7. Enter configuration mode on the interface where you want to enable IPv4 PBR by applying the route map.
    device(config)# interface ethernet 1/1/3
    IPv4 PBR can be enabled globally by which the route map is applied to all interfaces using the ip policy route-map command from global configuration mode.
  8. Enable PBR on the interface and specify the route map to be used.
    device(config-if-e1000-1/1/3)# ip policy route-map test-route

The following example shows the configuration steps to route routing traffic over an IPsec tunnel using PBR.

device(config)# interface tunnel 1
device(config-tnif-1)# vrf forwarding blue
device(config-tnif-1)# tunnel source ethernet 1/1/1
device(config-tnif-1)# tunnel destination 10.2.2.1
device(config-tnif-1)# tunnel mode ipsec ipv4
device(config-tnif-1)# tunnel protection ipsec profile prof-blue
device(config-tnif-1)# ip address 10.4.4.4/24
device(config-tnif-1)# exit
device(config)# ip access-list standard 99 
device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
device(config-std-ipacl-99)# exit
device(config)# route-map test-route permit 99
device(config-routemap test-route)# match ip address 99
device(config-routemap test-route)# set next-hop-ip-tunnel 1
device(config-routemap test-route)# end
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# vrf forwarding blue
device(config-if-e1000-1/1/3)# ip policy route-map test-route
device(config-if-e1000-1/1/3)# end

The following example shows the configuration steps to route routing traffic over a GRE tunnel using PBR.

device(config)# interface tunnel 1
device(config-tnif-1)# vrf forwarding blue
device(config-tnif-1)# tunnel source ethernet 1/1/1
device(config-tnif-1)# tunnel destination 10.2.2.1
device(config-tnif-1)# tunnel mode gre ip
device(config-tnif-1)# ip address 10.4.4.4/24
device(config-tnif-1)# exit
device(config)# ip access-list standard 99 
device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
device(config-std-ipacl-99)# exit
device(config)# route-map test-route permit 99
device(config-routemap test-route)# match ip address 99
device(config-routemap test-route)# set next-hop-ip-tunnel 1
device(config-routemap test-route)# end
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# vrf forwarding blue
device(config-if-e1000-1/1/3)# ip policy route-map test-route
device(config-if-e1000-1/1/3)# end